Workplace Privacy After Covid-19
Total Page:16
File Type:pdf, Size:1020Kb
WORKPLACE PRIVACY AFTER COVID-19 Digital Rights Program August 13, 2020 PUBLIC CITIZEN Workers Privacy After COVID-19 ACKNOWLEDGMENTS This report was written by Burcu Kilic, director of Public Citizen’s Digital Rights Program, with assistance from Scott Hulver, intern in the Digital Rights Program. It has greatly benefited from comments provided by Robert Weissman, Peter Maybarduk, Jane Chung and expert editing skills of David Rosen. Special thanks to Bret Thompson and James Smathers for their assistance with layout and graphic design. Cover image by James Smathers is licensed under Creative Commons. ABOUT PUBLIC CITIZEN Public Citizen is a national non-profit organization with more than 500,000 members and supporters. We represent consumer interests through lobbying, litigation, administrative advocacy, research, and public education on a broad range of issues including consumer rights in the marketplace, product safety, financial regulation, worker safety, safe and affordable health care, campaign finance reform and government ethics, fair trade, climate change, and corporate and government accountability. Contact Public Citizen Main Office Capitol Hill Texas Office 1600 20th Street NW 215 Pennsylvania Avenue SE, #3 309 E 11th Street, Suite 2 Washington, D.C. 20009 Washington, D.C. 20003 Austin, Texas 78701 Phone: 202-588-1000 Phone: 202-546-4996 Phone: 512 477-1155 For more information, please visit www.citizen.org. 2 PUBLIC CITIZEN Workers Privacy After COVID-19 TABLE OF CONTENTS Workplace Privacy After COVID-19 ..............................................................................4 Introduction ...................................................................................................................4 How Do Workplace-Surveillance Technologies Threaten Workers’ Privacy? ....6 Overview of COVID-19 Workplace-Surveillance Technologies ............................7 Best Practices for Employers Considering Introducing Workplace Surveillance .12 3 PUBLIC CITIZEN Workers Privacy After COVID-19 WORKPLACE PRIVACY AFTER COVID-19 The workplace is “where invasive technologies are normalized among captive populations of employees.” - Shoshana Zuboff, The Age of Surveillance Capitalism Introduction COVID-19 dramatically has changed how we think about the workplace. As businesses reopen and workers return, the spread of the coronavirus (COVID-19) is a serious concern. Amid the unrelenting first wave of infections and the prospect of recurring future waves, employers have been turning to new technologies to mitigate the risks – introducing a vast array of apps, wearables and other technologies. In a work setting, where activities are governed by a contractual or power relationship, many workers either must accept the new high-tech workplace surveillance or risk losing their jobs. Without sufficient government regulation and guidelines, employers using these technologies are invading workers' privacy to varying degrees. Some technologies may place various worker rights in jeopardy, including the right to equal treatment, by: • Tracking, monitoring, collecting and sharing personal data, including sensitive health data; • Directly sharing data with employers, bypassing worker consent; and • Posing increased cybersecurity risks. The speed at which these new technologies have been deployed is concerning. Fifty new apps and technologies have been released since the pandemic began, not accounting for existing, unchanged technologies that now are being marketed as workplace surveillance tools to combat COVID-19. On June 16 alone, both Fitbit and Amazon released new workplace surveillance tools. From an employer’s perspective, this rapid deployment is driven mainly by the urge to bring workers back to the workplace. But the invasion of privacy that workers face is alarming, especially considering that the effectiveness of these technologies in mitigating the spread of COVID-19 has not yet been established. 4 PUBLIC CITIZEN Workers Privacy After COVID-19 The default setting of most workplace surveillance apps is “mass surveillance by default.” For instance, Microsoft and UnitedHealth Group’s ProtectWell app sends COVID-19 diagnostic test results directly to the employer, bypassing the worker. Other apps don’t treat workers’ data as being subject to the requirements of the Health Insurance Portability and Accountability Act (HIPAA), meaning the data does not have to be securely handled and protected in accordance with HIPAA’s health information privacy provisions. Some The default setting of most wearables are tracking employees’ locations to identify and encourage behaviors. For workplace surveillance apps example, if a worker has not spent enough is “mass surveillance by time close to a sink, the app will identify them default.” as likely not having spent enough time washing their hands. This report identifies nearly 50 apps and technologies being introduced into the workplace. COVID-19 health tracking technology currently is being used by at least 32 employers1 to track at least 340,000 workers2 and is available to up to 14,0003 additional employers and almost 4 million workers4. The report describes what the apps are and how they work, highlighting specific privacy concerns. It concludes with a checklist of best practices for employers as they consider whether to introduce surveillance technologies into their workplaces. 1 We have identified 32 employers that have either self-reported or identified in the news as adopting these technologies. 2 340,000+ workers is an estimate based on how the company is rolling out the technology (office v. manufacturing plant, a particular location, etc.). In the absence of any information about who would be using it or how many workers would be tracked, we estimated based on the kind of technology and workforce size. 3 Many companies have released technologies embedded within existing systems and made these updates free to customers. We calculated the employers that could be using these technologies based on which businesses are existing customers and would have access to these updates. 4 Based on how many employers had access to these free updates, we calculated the size of their workforce, estimating employees using the existing technology. This number, although it could be lower, is likely significantly higher as our customer and workforce estimates were conservative. 5 PUBLIC CITIZEN Workers Privacy After COVID-19 How Do Workplace-Surveillance Technologies Threaten Workers’ Privacy? Listed below are three apps being introduced into the workplace that invade workers’ privacy. For each product, workers download the app onto their mobile phones and periodically fill out a survey of self-reported medical information, such as COVID-19 symptoms and temperature. Employers can access workers’ information through a reporting platform, which allows employers to view self-reported medical information and identify workers who could have been exposed to other sick workers. Here are some of their most alarming privacy-violating features, as described by their makers: ProtectWell by Microsoft and United Health • “Employers can direct their workers to a streamlined COVID-19 testing process that enables closed-loop ordering and reporting of test results directly back to employers.” - Microsoft Press Release • “Any information disclosed to us in connection with the Site and the ProtectWell App is not protected health information, as defined under the Health Insurance Portability and Accountability Act of 1996 (‘HIPAA’)...” - ProtectWell Privacy Policy • “We may obtain additional information about you from third parties such as marketers, partners, researchers, and others. We may combine information that we collect from you with information about you that we obtain from such third parties and information derived from any other subscription, product, or service we provide.” - ProtectWell Privacy Policy 6 PUBLIC CITIZEN Workers Privacy After COVID-19 Healthcheck by Stratum • “Our workers and agents may view your Personal Information...” - Healthcheck Privacy Policy • “If you are accessing on a mobile device, we will automatically collect personal data including device, content and usage data… We also collect IP address access location to determine your current location…” - Healthcheck Privacy Policy COVID-19 Worker Safety and Business Continuity Tracker by Pegasystems • Your personal information may be transferred, processed and stored outside the country where your information was collected by using or attending a Service...” - Pegasystems Privacy Notice Overview of COVID-19 Workplace-Surveillance Technologies Table 1: Apps in which Workers Self-report Health Information App How it works Who’s Using it? Pegasystems Tool for employers to build custom Unclear; introduced as part of an existing COVID-19 symptom survey apps; data platform, to which these 60 companies have is aggregated in a central dashboard access for the employer. Back to Work Workers fill out a pre-set survey Unclear; embedded in a platform used by 100+ (Cordata) embedded in the existing app; data is companies aggregated in a central dashboard. Arcoro Worker survey built into existing time Titan roofing, a small business in clock app; data stored on the cloud. Massachusetts Workforce Tool for employers to build custom Unclear; separate app from what current Safety (Appian) COVID-19 symptom survey apps; data customers use is aggregated in a central dashboard for the employer. Landing AI Camera monitoring system to identify Undisclosed